Score
Designs and performs audit processes and measurement frameworks to evaluate organizational compliance with privacy laws, policies, and contractual obligations; builds tooling and workflows to submit and track opt-out and deletion requests, catalog request-submission procedures, and measure response and reply rates to quantify compliance.
This study addresses widespread compliance issues in GitHub Actions workflows, such as excessive permissions and weak secret management. It proposes the first documentation-driven compliance checking framework, which derives a 30-item checklist from official documentation and implements a hybrid auditing pipeline combining large language models (LLMs) with expert oversight. The authors automatically evaluate 95 real-world Java workflows using four open-source LLMs, employ GPT-5 as a conflict arbitrator, and integrate manual review into a multi-tiered validation system. Experimental results reveal an overall compliance rate of only 28%, with permission control as low as 4%. The proposed approach reduces manual verification effort by 81% while achieving 87% agreement with expert judgments, significantly enhancing audit efficiency and reproducibility.
This study addresses the lack of systematic comparative analysis in business process compliance monitoring, particularly for non-conformance checking techniques. Through a systematic literature review (SLR), process mining, compliance modeling, and qualitative comparative analysis, it maps real-world applications across domains, operational workflows, technical foundations, and result representations. The analysis identifies key implementation barriers—especially pervasive human dependence and the absence of standardized evaluation criteria. As the first structured survey framework dedicated to non-conformance checking, the study introduces a standardized, multi-dimensional evaluation framework that clarifies commonalities and distinctions across the technical landscape. It further proposes an extensible theoretical pathway and practical guidelines for automated compliance monitoring. This work provides a methodological foundation and strategic direction for both academic research and industrial deployment. (149 words)
Traditional compliance assessments rely on point-in-time audits and self-attestation, which struggle to enable continuous, cross-organizational, and traceable verification of security controls in multi-vendor environments. This work proposes a permissioned blockchain-based Third-Party Risk Assessment (TPRA) framework that transforms static compliance into a dynamic, repeatable, and verifiable continuous governance mechanism through smart contract–automated evaluation workflows, multi-party governance protocols, and longitudinal state tracking. The study contributes an actionable TPRA architecture, along with complementary compliance maturity metrics and a qualitative model, enabling quantification and long-term validation of security control implementation maturity across organizational boundaries and time periods.
This work proposes the Automated Compliance Engine (ACE), a novel trust and reputation system that overcomes the limitations of existing approaches relying on subjective ratings or coarse-grained compliance judgments. ACE uniquely models regulatory compliance as a dynamic, multi-dimensional trust metric by formalizing policies using obligation-centered logic and continuously auditing system logs. It quantifies compliance through a scoring mechanism that accounts for the volume, duration, breadth, and criticality of violations. Experimental evaluation on a synthetic hospital dataset demonstrates that ACE accurately detects complex violations of HIPAA and GDPR regulations. The resulting compliance scores offer significantly greater expressiveness and practical utility compared to traditional binary compliance assessments, enabling fine-grained and interpretable trust evaluations.
Developers face significant practical challenges in implementing data privacy regulations (e.g., GDPR, CPRA) and lack adequate automated tooling to support compliance. Method: We conducted a mixed-methods study with 68 software developers—including structured surveys, in-depth interviews, and statistical modeling—to systematically identify their core requirements for privacy-compliance tools and the factors influencing those needs. Contribution/Results: We find that developers strongly prefer integrated, context-aware tooling; moreover, those with greater privacy experience place higher emphasis on tool reliability and legal alignment. Our analysis reveals a statistically significant positive association between developers’ privacy expertise and their demand for sophisticated, regulation-aware tool features. This study is the first empirical investigation centered explicitly on developers’ privacy-compliance enablement needs, thereby filling a critical gap in the literature. The findings provide foundational, evidence-based guidance for designing next-generation, generative-AI–powered privacy compliance automation tools.
This work addresses the compliance challenges in federated data processing arising from heterogeneous cross-organizational access policies, regulatory discrepancies, and long-running workflows. To tackle these issues, the paper proposes a compliance-aware federated data processing framework that uniquely integrates large language models (LLMs) with a “policy-as-code” approach. This integration enables the automatic translation of natural language descriptions of legal and organizational compliance requirements into executable machine-interpretable policies. An orchestration engine then enforces these policies dynamically across end-to-end workflows. Evaluation of the prototype system demonstrates that the proposed method effectively harmonizes multi-source compliance rules, significantly enhancing both compliance assurance and deployment feasibility in federated environments.
This work addresses the lack of traceable and tamper-resistant transparency mechanisms in large language models (LLMs) deployed in high-stakes decision-making contexts, which undermines accountability. To bridge this gap, the paper introduces the first LLM lifecycle auditing framework that integrates technical provenance with governance records. It proposes a reference architecture enabling cross-organizational traceability and implements a lightweight, open-source Python-based auditing layer. By leveraging append-only logs, event emitters, structured metadata, and an auditor interface, the system seamlessly integrates into existing LLM workflows with minimal intrusiveness. This design ensures complete, tamper-evident traceability across critical stages—including training, deployment, and monitoring—thereby facilitating robust accountability and responsibility attribution throughout the model’s lifecycle.
This study addresses the limitations of prevailing AI compliance approaches, which often rely on one-time audits and fail to meet the European Union AI Act’s demands for continuous oversight and behavioral drift detection. To bridge this gap, the authors propose a metrics-based governance framework (govllm) that leverages runtime observability to generate ongoing compliance signals. The framework employs an ensemble of small language models (1.7B–7B parameters), each trained on distinct regulatory criteria, to dynamically evaluate system outputs against multidimensional requirements such as GDPR and the EU AI Act within local environments. Disagreements among reviewers are modeled as indicators of regulatory uncertainty, prompting human intervention. Evaluation on 49 annotated samples reveals a maximum inter-model agreement of 69.1% (phi4-mini), underscoring that no single model generalizes across all compliance criteria, while also uncovering three distinct failure modes and significant positional bias in assessments.
This study addresses the challenges of assessing compliance between organizational cybersecurity policies and abstract security control frameworks such as NIST SP 800-53, which are often time-consuming, difficult to standardize, and lack traceability. To overcome these limitations, the authors propose PROPAGATE, a novel framework that leverages large language models (LLMs) to automate control-level compliance evaluation for the first time. By integrating both open-source and closed-source LLMs, the framework automatically retrieves relevant policy text, evaluates coverage across 1,007 security controls, and generates interpretable gap analyses with actionable improvement recommendations. Experimental results on two real-world organizational policy corpora demonstrate high effectiveness, achieving F1 scores of 88.54 and 82.31, respectively, thereby enabling traceable and explainable compliance enhancement.